You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

PushCertificateParserTest.java 15KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389
  1. /*
  2. * Copyright (C) 2015, Google Inc.
  3. *
  4. * This program and the accompanying materials are made available
  5. * under the terms of the Eclipse Distribution License v1.0 which
  6. * accompanies this distribution, is reproduced below, and is
  7. * available at http://www.eclipse.org/org/documents/edl-v10.php
  8. *
  9. * All rights reserved.
  10. *
  11. * Redistribution and use in source and binary forms, with or
  12. * without modification, are permitted provided that the following
  13. * conditions are met:
  14. *
  15. * - Redistributions of source code must retain the above copyright
  16. * notice, this list of conditions and the following disclaimer.
  17. *
  18. * - Redistributions in binary form must reproduce the above
  19. * copyright notice, this list of conditions and the following
  20. * disclaimer in the documentation and/or other materials provided
  21. * with the distribution.
  22. *
  23. * - Neither the name of the Eclipse Foundation, Inc. nor the
  24. * names of its contributors may be used to endorse or promote
  25. * products derived from this software without specific prior
  26. * written permission.
  27. *
  28. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND
  29. * CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES,
  30. * INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
  31. * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
  32. * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR
  33. * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
  34. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
  35. * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  36. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
  37. * CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
  38. * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
  39. * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
  40. * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  41. */
  42. package org.eclipse.jgit.transport;
  43. import static java.nio.charset.StandardCharsets.UTF_8;
  44. import static org.junit.Assert.assertEquals;
  45. import static org.junit.Assert.assertFalse;
  46. import static org.junit.Assert.assertNotEquals;
  47. import static org.junit.Assert.assertNotNull;
  48. import static org.junit.Assert.assertNull;
  49. import static org.junit.Assert.assertTrue;
  50. import static org.junit.Assert.fail;
  51. import java.io.ByteArrayInputStream;
  52. import java.io.EOFException;
  53. import java.io.IOException;
  54. import java.io.InputStreamReader;
  55. import java.io.Reader;
  56. import java.io.StringReader;
  57. import org.eclipse.jgit.errors.PackProtocolException;
  58. import org.eclipse.jgit.internal.storage.dfs.DfsRepositoryDescription;
  59. import org.eclipse.jgit.internal.storage.dfs.InMemoryRepository;
  60. import org.eclipse.jgit.lib.Config;
  61. import org.eclipse.jgit.lib.Constants;
  62. import org.eclipse.jgit.lib.ObjectId;
  63. import org.eclipse.jgit.lib.Repository;
  64. import org.eclipse.jgit.transport.PushCertificate.NonceStatus;
  65. import org.junit.Before;
  66. import org.junit.Test;
  67. /** Test for push certificate parsing. */
  68. public class PushCertificateParserTest {
  69. // Example push certificate generated by C git 2.2.0.
  70. private static final String INPUT = "001ccertificate version 0.1\n"
  71. + "0041pusher Dave Borowitz <dborowitz@google.com> 1433954361 -0700\n"
  72. + "0024pushee git://localhost/repo.git\n"
  73. + "002anonce 1433954361-bde756572d665bba81d8\n"
  74. + "0005\n"
  75. + "00680000000000000000000000000000000000000000"
  76. + " 6c2b981a177396fb47345b7df3e4d3f854c6bea7"
  77. + " refs/heads/master\n"
  78. + "0022-----BEGIN PGP SIGNATURE-----\n"
  79. + "0016Version: GnuPG v1\n"
  80. + "0005\n"
  81. + "0045iQEcBAABAgAGBQJVeGg5AAoJEPfTicJkUdPkUggH/RKAeI9/i/LduuiqrL/SSdIa\n"
  82. + "00459tYaSqJKLbXz63M/AW4Sp+4u+dVCQvnAt/a35CVEnpZz6hN4Kn/tiswOWVJf4CO7\n"
  83. + "0045htNubGs5ZMwvD6sLYqKAnrM3WxV/2TbbjzjZW6Jkidz3jz/WRT4SmjGYiEO7aA+V\n"
  84. + "00454ZdIS9f7sW5VsHHYlNThCA7vH8Uu48bUovFXyQlPTX0pToSgrWV3JnTxDNxfn3iG\n"
  85. + "0045IL0zTY/qwVCdXgFownLcs6J050xrrBWIKqfcWr3u4D2aCLyR0v+S/KArr7ulZygY\n"
  86. + "0045+SOklImn8TAZiNxhWtA6ens66IiammUkZYFv7SSzoPLFZT4dC84SmGPWgf94NoQ=\n"
  87. + "000a=XFeC\n"
  88. + "0020-----END PGP SIGNATURE-----\n"
  89. + "0012push-cert-end\n";
  90. // Same push certificate, with all trailing newlines stripped.
  91. // (Note that the canonical signed payload is the same, so the same signature
  92. // is still valid.)
  93. private static final String INPUT_NO_NEWLINES = "001bcertificate version 0.1"
  94. + "0040pusher Dave Borowitz <dborowitz@google.com> 1433954361 -0700"
  95. + "0023pushee git://localhost/repo.git"
  96. + "0029nonce 1433954361-bde756572d665bba81d8"
  97. + "0004"
  98. + "00670000000000000000000000000000000000000000"
  99. + " 6c2b981a177396fb47345b7df3e4d3f854c6bea7"
  100. + " refs/heads/master"
  101. + "0021-----BEGIN PGP SIGNATURE-----"
  102. + "0015Version: GnuPG v1"
  103. + "0004"
  104. + "0044iQEcBAABAgAGBQJVeGg5AAoJEPfTicJkUdPkUggH/RKAeI9/i/LduuiqrL/SSdIa"
  105. + "00449tYaSqJKLbXz63M/AW4Sp+4u+dVCQvnAt/a35CVEnpZz6hN4Kn/tiswOWVJf4CO7"
  106. + "0044htNubGs5ZMwvD6sLYqKAnrM3WxV/2TbbjzjZW6Jkidz3jz/WRT4SmjGYiEO7aA+V"
  107. + "00444ZdIS9f7sW5VsHHYlNThCA7vH8Uu48bUovFXyQlPTX0pToSgrWV3JnTxDNxfn3iG"
  108. + "0044IL0zTY/qwVCdXgFownLcs6J050xrrBWIKqfcWr3u4D2aCLyR0v+S/KArr7ulZygY"
  109. + "0044+SOklImn8TAZiNxhWtA6ens66IiammUkZYFv7SSzoPLFZT4dC84SmGPWgf94NoQ="
  110. + "0009=XFeC"
  111. + "001f-----END PGP SIGNATURE-----"
  112. + "0011push-cert-end";
  113. private Repository db;
  114. @Before
  115. public void setUp() {
  116. db = new InMemoryRepository(new DfsRepositoryDescription("repo"));
  117. }
  118. private static SignedPushConfig newEnabledConfig() {
  119. Config cfg = new Config();
  120. cfg.setString("receive", null, "certnonceseed", "sekret");
  121. return SignedPushConfig.KEY.parse(cfg);
  122. }
  123. private static SignedPushConfig newDisabledConfig() {
  124. return SignedPushConfig.KEY.parse(new Config());
  125. }
  126. @Test
  127. public void noCert() throws Exception {
  128. PushCertificateParser parser =
  129. new PushCertificateParser(db, newEnabledConfig());
  130. assertTrue(parser.enabled());
  131. assertNull(parser.build());
  132. ObjectId oldId = ObjectId.zeroId();
  133. ObjectId newId =
  134. ObjectId.fromString("deadbeefdeadbeefdeadbeefdeadbeefdeadbeef");
  135. String line = oldId.name() + " " + newId.name() + " refs/heads/master";
  136. ReceiveCommand cmd = BaseReceivePack.parseCommand(line);
  137. parser.addCommand(cmd);
  138. parser.addCommand(line);
  139. assertNull(parser.build());
  140. }
  141. @Test
  142. public void disabled() throws Exception {
  143. PacketLineIn pckIn = newPacketLineIn(INPUT);
  144. PushCertificateParser parser =
  145. new PushCertificateParser(db, newDisabledConfig());
  146. assertFalse(parser.enabled());
  147. assertNull(parser.build());
  148. parser.receiveHeader(pckIn, false);
  149. parser.addCommand(pckIn.readString());
  150. assertEquals(PushCertificateParser.BEGIN_SIGNATURE, pckIn.readString());
  151. parser.receiveSignature(pckIn);
  152. assertNull(parser.build());
  153. }
  154. @Test
  155. public void disabledParserStillRequiresCorrectSyntax() throws Exception {
  156. PacketLineIn pckIn = newPacketLineIn("001ccertificate version XYZ\n");
  157. PushCertificateParser parser =
  158. new PushCertificateParser(db, newDisabledConfig());
  159. assertFalse(parser.enabled());
  160. try {
  161. parser.receiveHeader(pckIn, false);
  162. fail("Expected PackProtocolException");
  163. } catch (PackProtocolException e) {
  164. assertEquals(
  165. "Push certificate has missing or invalid value for certificate"
  166. + " version: XYZ",
  167. e.getMessage());
  168. }
  169. assertNull(parser.build());
  170. }
  171. @Test
  172. public void parseCertFromPktLine() throws Exception {
  173. PacketLineIn pckIn = newPacketLineIn(INPUT);
  174. PushCertificateParser parser =
  175. new PushCertificateParser(db, newEnabledConfig());
  176. parser.receiveHeader(pckIn, false);
  177. parser.addCommand(pckIn.readString());
  178. assertEquals(PushCertificateParser.BEGIN_SIGNATURE, pckIn.readString());
  179. parser.receiveSignature(pckIn);
  180. PushCertificate cert = parser.build();
  181. assertEquals("0.1", cert.getVersion());
  182. assertEquals("Dave Borowitz", cert.getPusherIdent().getName());
  183. assertEquals("dborowitz@google.com",
  184. cert.getPusherIdent().getEmailAddress());
  185. assertEquals(1433954361000L, cert.getPusherIdent().getWhen().getTime());
  186. assertEquals(-7 * 60, cert.getPusherIdent().getTimeZoneOffset());
  187. assertEquals("git://localhost/repo.git", cert.getPushee());
  188. assertEquals("1433954361-bde756572d665bba81d8", cert.getNonce());
  189. assertNotEquals(cert.getNonce(), parser.getAdvertiseNonce());
  190. assertEquals(PushCertificate.NonceStatus.BAD, cert.getNonceStatus());
  191. assertEquals(1, cert.getCommands().size());
  192. ReceiveCommand cmd = cert.getCommands().get(0);
  193. assertEquals("refs/heads/master", cmd.getRefName());
  194. assertEquals(ObjectId.zeroId(), cmd.getOldId());
  195. assertEquals("6c2b981a177396fb47345b7df3e4d3f854c6bea7",
  196. cmd.getNewId().name());
  197. assertEquals(concatPacketLines(INPUT, 0, 6), cert.toText());
  198. assertEquals(concatPacketLines(INPUT, 0, 17), cert.toTextWithSignature());
  199. String signature = concatPacketLines(INPUT, 6, 17);
  200. assertTrue(signature.startsWith(PushCertificateParser.BEGIN_SIGNATURE));
  201. assertTrue(signature.endsWith(PushCertificateParser.END_SIGNATURE + "\n"));
  202. assertEquals(signature, cert.getSignature());
  203. }
  204. @Test
  205. public void parseCertFromPktLineNoNewlines() throws Exception {
  206. PacketLineIn pckIn = newPacketLineIn(INPUT_NO_NEWLINES);
  207. PushCertificateParser parser =
  208. new PushCertificateParser(db, newEnabledConfig());
  209. parser.receiveHeader(pckIn, false);
  210. parser.addCommand(pckIn.readString());
  211. assertEquals(PushCertificateParser.BEGIN_SIGNATURE, pckIn.readString());
  212. parser.receiveSignature(pckIn);
  213. PushCertificate cert = parser.build();
  214. assertEquals("0.1", cert.getVersion());
  215. assertEquals("Dave Borowitz", cert.getPusherIdent().getName());
  216. assertEquals("dborowitz@google.com",
  217. cert.getPusherIdent().getEmailAddress());
  218. assertEquals(1433954361000L, cert.getPusherIdent().getWhen().getTime());
  219. assertEquals(-7 * 60, cert.getPusherIdent().getTimeZoneOffset());
  220. assertEquals("git://localhost/repo.git", cert.getPushee());
  221. assertEquals("1433954361-bde756572d665bba81d8", cert.getNonce());
  222. assertNotEquals(cert.getNonce(), parser.getAdvertiseNonce());
  223. assertEquals(PushCertificate.NonceStatus.BAD, cert.getNonceStatus());
  224. assertEquals(1, cert.getCommands().size());
  225. ReceiveCommand cmd = cert.getCommands().get(0);
  226. assertEquals("refs/heads/master", cmd.getRefName());
  227. assertEquals(ObjectId.zeroId(), cmd.getOldId());
  228. assertEquals("6c2b981a177396fb47345b7df3e4d3f854c6bea7",
  229. cmd.getNewId().name());
  230. // Canonical signed payload has reinserted newlines.
  231. assertEquals(concatPacketLines(INPUT, 0, 6), cert.toText());
  232. String signature = concatPacketLines(INPUT, 6, 17);
  233. assertTrue(signature.startsWith(PushCertificateParser.BEGIN_SIGNATURE));
  234. assertTrue(signature.endsWith(PushCertificateParser.END_SIGNATURE + "\n"));
  235. assertEquals(signature, cert.getSignature());
  236. }
  237. @Test
  238. public void testConcatPacketLines() throws Exception {
  239. String input = "000bline 1\n000bline 2\n000bline 3\n";
  240. assertEquals("line 1\n", concatPacketLines(input, 0, 1));
  241. assertEquals("line 1\nline 2\n", concatPacketLines(input, 0, 2));
  242. assertEquals("line 2\nline 3\n", concatPacketLines(input, 1, 3));
  243. assertEquals("line 2\nline 3\n", concatPacketLines(input, 1, 4));
  244. }
  245. @Test
  246. public void testConcatPacketLinesInsertsNewlines() throws Exception {
  247. String input = "000bline 1\n000aline 2000bline 3\n";
  248. assertEquals("line 1\n", concatPacketLines(input, 0, 1));
  249. assertEquals("line 1\nline 2\n", concatPacketLines(input, 0, 2));
  250. assertEquals("line 2\nline 3\n", concatPacketLines(input, 1, 3));
  251. assertEquals("line 2\nline 3\n", concatPacketLines(input, 1, 4));
  252. }
  253. @Test
  254. public void testParseReader() throws Exception {
  255. Reader reader = new StringReader(concatPacketLines(INPUT, 0, 18));
  256. PushCertificate streamCert = PushCertificateParser.fromReader(reader);
  257. PacketLineIn pckIn = newPacketLineIn(INPUT);
  258. PushCertificateParser pckParser =
  259. new PushCertificateParser(db, newEnabledConfig());
  260. pckParser.receiveHeader(pckIn, false);
  261. pckParser.addCommand(pckIn.readString());
  262. assertEquals(PushCertificateParser.BEGIN_SIGNATURE, pckIn.readString());
  263. pckParser.receiveSignature(pckIn);
  264. PushCertificate pckCert = pckParser.build();
  265. // Nonce status is unsolicited since this was not parsed in the context of
  266. // the wire protocol; as a result, certs are not actually equal.
  267. assertEquals(NonceStatus.UNSOLICITED, streamCert.getNonceStatus());
  268. assertEquals(pckCert.getVersion(), streamCert.getVersion());
  269. assertEquals(pckCert.getPusherIdent().getName(),
  270. streamCert.getPusherIdent().getName());
  271. assertEquals(pckCert.getPusherIdent().getEmailAddress(),
  272. streamCert.getPusherIdent().getEmailAddress());
  273. assertEquals(pckCert.getPusherIdent().getWhen().getTime(),
  274. streamCert.getPusherIdent().getWhen().getTime());
  275. assertEquals(pckCert.getPusherIdent().getTimeZoneOffset(),
  276. streamCert.getPusherIdent().getTimeZoneOffset());
  277. assertEquals(pckCert.getPushee(), streamCert.getPushee());
  278. assertEquals(pckCert.getNonce(), streamCert.getNonce());
  279. assertEquals(pckCert.getSignature(), streamCert.getSignature());
  280. assertEquals(pckCert.toText(), streamCert.toText());
  281. assertEquals(pckCert.getCommands().size(), streamCert.getCommands().size());
  282. ReceiveCommand pckCmd = pckCert.getCommands().get(0);
  283. ReceiveCommand streamCmd = streamCert.getCommands().get(0);
  284. assertEquals(pckCmd.getRefName(), streamCmd.getRefName());
  285. assertEquals(pckCmd.getOldId(), streamCmd.getOldId());
  286. assertEquals(pckCmd.getNewId().name(), streamCmd.getNewId().name());
  287. }
  288. @Test
  289. public void testParseString() throws Exception {
  290. String str = concatPacketLines(INPUT, 0, 18);
  291. assertEquals(
  292. PushCertificateParser.fromReader(new StringReader(str)),
  293. PushCertificateParser.fromString(str));
  294. }
  295. @Test
  296. public void testParseMultipleFromStream() throws Exception {
  297. String input = concatPacketLines(INPUT, 0, 17);
  298. assertFalse(input.contains(PushCertificateParser.END_CERT));
  299. input += input;
  300. Reader reader = new InputStreamReader(
  301. new ByteArrayInputStream(Constants.encode(input)), UTF_8);
  302. assertNotNull(PushCertificateParser.fromReader(reader));
  303. assertNotNull(PushCertificateParser.fromReader(reader));
  304. assertEquals(-1, reader.read());
  305. assertNull(PushCertificateParser.fromReader(reader));
  306. }
  307. @Test
  308. public void testMissingPusheeField() throws Exception {
  309. // Omit pushee line from existing cert. (This means the signature would not
  310. // match, but we're not verifying it here.)
  311. String input = INPUT.replace("0024pushee git://localhost/repo.git\n", "");
  312. assertFalse(input.contains(PushCertificateParser.PUSHEE));
  313. PacketLineIn pckIn = newPacketLineIn(input);
  314. PushCertificateParser parser =
  315. new PushCertificateParser(db, newEnabledConfig());
  316. parser.receiveHeader(pckIn, false);
  317. parser.addCommand(pckIn.readString());
  318. assertEquals(PushCertificateParser.BEGIN_SIGNATURE, pckIn.readString());
  319. parser.receiveSignature(pckIn);
  320. PushCertificate cert = parser.build();
  321. assertEquals("0.1", cert.getVersion());
  322. assertNull(cert.getPushee());
  323. assertFalse(cert.toText().contains(PushCertificateParser.PUSHEE));
  324. }
  325. private static String concatPacketLines(String input, int begin, int end)
  326. throws IOException {
  327. StringBuilder result = new StringBuilder();
  328. int i = 0;
  329. PacketLineIn pckIn = newPacketLineIn(input);
  330. while (i < end) {
  331. String line;
  332. try {
  333. line = pckIn.readString();
  334. } catch (EOFException e) {
  335. break;
  336. }
  337. if (++i > begin) {
  338. result.append(line).append('\n');
  339. }
  340. }
  341. return result.toString();
  342. }
  343. private static PacketLineIn newPacketLineIn(String input) {
  344. return new PacketLineIn(new ByteArrayInputStream(Constants.encode(input)));
  345. }
  346. }